The 21st OSE Symposium, held in Munich on January 30, 2026, under the title “Data Dynamics – Use Cases Between Regulation and Value Creation,” brought together experts from the fields of technology, academia, business, and law.

Following introductory remarks by Stephan Peters (OSE; Deposix Software Escrow GmbH, Munich) and Dr. Christiane Bierekoven, Attorney-at-Law (davit, Berlin; Dr. Ganteführer, Marquardt & Partner mbB, Düsseldorf), a wide range of specialist presentations explored the topic and its inherent tensions from various perspectives.

The event concluded with a panel discussion, during which Dr. Thomas Thalhofer, Attorney-at-Law (Noerr PartG mbB, Munich) addressed questions to the speakers in order to further explore and deepen the topics covered in the presentations.

1. Case Law Update

Conference chair Isabell Conrad, Attorney-at-Law (OSE; CSW Rechtsanwälte Partnerschaft mbB, Munich) opened the symposium with an overview of the case law from the previous year. Her presentation, supported by a script of almost one hundred pages, used numerous examples to illustrate how case law is shaping the interaction between regulation and (digital) value creation.

In the area of standard terms and conditions, the topics discussed ranged from liability for in-app purchases made by minors (Federal Court of Justice (BGH), judgment of 24 September 2025 – Case No. 2 O 64/23), to the validity of online terms and conditions in “analogue” contract conclusions (BGH, judgment of 10 July 2025 – Case No. III ZR 59/24), and the strengthening of termination rights in online dating services (BGH, judgment of 17 July 2025 – Case No. III ZR 388/23). Of particular practical relevance were the decisions concerning unilateral changes to services and price increases for Amazon services (Munich Regional Court I, judgment of 16 December 2025 – Case No. 33 O 3266/24; Düsseldorf Higher Regional Court, judgment of 30 October 2025 – Case No. I-20 U 19/25), as well as authentication procedures for blocking SIM cards (BGH, judgment of 23 October 2025 – Case No. III ZR 147/24).

She placed particular emphasis on the large number of decisions concerning the German Distance Learning Protection Act (FernUSG), which has increasingly come into focus in the age of AI. The case law addressed, among other matters, the applicability of the FernUSG to online coaching. In two cases, the BGH affirmed its applicability and, consequently, the requirement for regulatory approval (BGH, judgment of 12 June 2025 – Case No. III ZR 109/24; BGH, judgment of 2 October 2025 – Case No. III ZR 173/24). By contrast, the Hamm Higher Regional Court denied its applicability in one case due to the absence of any monitoring of learning progress (order of 15 October 2025 – Case No. 12 U 63/25).

In digital commerce, the topics included the distinction between “Click & Collect” and “Click & Reserve” offerings (Stuttgart Higher Regional Court, judgment of 25 November 2025 – Case No. 6 Ukl 1/25), as well as the classification of Amazon Store (General Court of the European Union, judgment of 19 November 2025 – Case T-367/23) and Zalando (General Court, judgment of 3 September 2025 – Case T-348/23) as Very Large Online Platforms (VLOPs) under the Digital Services Act (DSA). The Court of Justice of the European Union (CJEU) and the BGH addressed the “buy now, pay later” offering of an online retailer (CJEU, judgment of 15 May 2025 – Case C-100/24; BGH, judgment of 11 September 2025 – Case No. I ZR 14/23). Platform liability was further clarified by the CJEU’s Russmedia decision (CJEU, judgment of 2 December 2025 – Case C-492/23).

In copyright law, she refrained from discussing the widely known decision of Munich Regional Court I in the GEMA/OpenAI case (judgment of 11 November 2025 – Case No. 42 O 14139/24), but instead drew attention to the less well-known decision in the proceedings brought by Getty Images against Stability AI in connection with AI-generated images (High Court of Justice, London, judgment of 4 November 2025 – [2025] EWHC 2863 (Ch)). In competition law, divergent decisions illustrate the legal uncertainty surrounding AI training using social media data (Cologne Higher Regional Court, judgment of 23 May 2025 – Case No. 15 Ukl 2/25; District Court of Amsterdam, 19 May 2025 – Case No. 10795074 Cv FORM 23-14577). The classification of Apple as an undertaking of paramount significance for competition across markets (BGH, order of 18 March 2025 – Case No. KVB 61/23) confirmed the trend towards stricter platform oversight. The overview was rounded off by a data protection decision concerning the (lack of) guest access options on online marketplaces (Hamburg Higher Regional Court, judgment of 27 February 2025 – Case No. 5 U 30/24). Overall, it was a year in which case law drew the boundaries for digital business models more tightly while at the same time providing greater clarity.

2. Keynote: Quantum Technologies and the Quantum Act – Regulation or Regulatory Intervention?

The keynote by Prof. Dr. Tommaso Calarco (Institute for Quantum Control, Forschungszentrum Jülich) addressed the question of how quantum technologies can be supported by policy and regulation in the future. The starting point was the idea that we are entering the decade of practical quantum technology applications and moving beyond the stage of purely academic research. Cryptography, for example, was mentioned as a field of application during the subsequent panel discussion. With today’s technology, decrypting encrypted data is ultimately a matter of computing power and time. With quantum technology, by contrast, this could become entirely impossible, although such developments may still be some 15 to 20 years away, should they materialise.

Governments around the world are scaling up their investments, while the private sector is also significantly accelerating its activities. Europe must take action. The “European Declaration on Quantum Technologies”, signed by all 27 EU Member States, was presented as the relevant policy framework. Its aim is to make Europe the “Quantum Continent”.

The European “Quantum Vision” is to establish Europe as a global hub for quantum technology that safeguards technological sovereignty, combines scientific excellence with industrial strength, and transforms research into applications and market impact.

Against this background, the concept of regulation through a “Quantum Act” was outlined. Overall, it became clear that regulation should not be understood as an obstacle in this context, but rather as an instrument for enabling research, innovation, development and industrial implementation.

3. Thematic Session 1: Data, Deals, Take-Off: Cloud Switching and Competition Law

a) Data upon Data – and Its Price under Competition Law

The first thematic session, moderated by Dr. Michaela Westrup, Attorney-at-Law (Reed Smith LLP, Munich), was opened by Prof. Dr. Peter Georg Picht (University of Zurich) and dealt with the relevance of information exchange under competition law.

The presentation began by outlining the fundamental structures of EU competition law governing information exchange, in particular its classification under Article 101 TFEU (agreements and/or concerted practices). It was emphasised that enforcement activity in the area of information exchange is noticeably increasing. Criteria were presented for assessing the sensitivity of information exchanged. These include, for example, the nature of the information – prices or contractual terms being particularly sensitive – and the age of the information, with current data being especially critical.

Various case studies illustrated that algorithmic systems create new challenges. From the United States, the proceedings United States et al. v. RealPage Inc. (1:24-cv-00710, M.D.N.C.) and Gibson v. Cendyn Grp., LLC (93 F.4th 1125) were discussed, both of which concerned algorithmic recommendations regarding prices or contractual terms. At European level, numerous other proceedings were presented, including before the CJEU (judgment of 21 January 2016 – C-74/14 – Eturas) and the European Commission (Delivery Hero/Glovo).

The presentation concluded with a “self-assessment” that examines, among other factors, the strategic nature of an information exchange – particularly against the background that competition law must always preserve businesses’ ability to make independent commercial decisions. Finally, information exchange was also considered from the perspective of the DMA and the Data Act.

b) Contract Drafting for Cloud Switching – Practical Blueprints

The presentation by Prof. Dr. Boris P. Paal (Technical University of Munich) focused on the Data Act requirements governing cloud switching and thus on one of the most practically relevant aspects of the new legal framework. The primary focus was Chapter VI (Articles 23–31), which governs switching between data processing services and, despite the relatively small number of provisions, represents a significant intervention in existing contractual structures. Facilitating cloud switching is intended to strengthen the portability and interoperability of data and services and prevent lock-in effects.

After presenting the fundamentals of the Data Act, the presentation turned to the catalogue of obligations applicable to cloud switching, covering contractual arrangements, information obligations, commercial requirements, technical obligations and duties of conduct. In this context, reference was made to the European Commission’s recommendations on non-binding model contractual terms for cloud computing contracts.

The EU legislature’s Digital Omnibus initiative was also discussed. It envisages amendments to the Data Act, including exemptions from certain cloud switching requirements, for example for customised data processing services and for SMEs in relation to contracts concluded before 12 September 2025.

c) Moving Made Easy: Technologies and Architectural Patterns for Cloud Switching

Eckhard Eilers (Woodmark Consulting GmbH, Munich) examined cloud switching from a technical perspective. He demonstrated that the regulatory requirements of the Data Act alone do not guarantee that switching will work smoothly in practice.

Eilers first presented the main drivers behind cloud migrations and cloud exits, including disappointed expectations regarding cost-saving potential and the desire to reduce dependency on US-based services.

He then outlined possible target environments for a switch. In addition to hyperscalers such as AWS, Microsoft Azure and Google Cloud, European providers including OVHcloud, Open Telekom Cloud, IONOS and Exoscale were compared. It became clear that, while the European market offers alternatives, these often do not yet match the technical capabilities of the hyperscalers.

A central point was that portability needs to be considered from the outset when planning a cloud solution. Eilers presented various abstraction approaches that can facilitate subsequent portability. On the one hand, he examined abstraction in IaC (Infrastructure as Code) and cloud management, such as the use of cloud-agnostic IaC code (e.g. Terraform or OpenTofu) and multi-cloud management platforms (HPE Morpheus, Rancher, etc.). On the other hand, he presented abstraction approaches at application level, such as integrating an adapter layer to enable different providers to be connected.

Finally, he pointed out that the sheer volume of data – for example, three terabytes of documents – can itself pose a problem and therefore needs to be taken into account.

Overall, it became clear that cloud switching is also an architectural and strategic task and that, without appropriate preparation, even the Data Act cannot make a switch straightforward in practice.

4. Thematic Session 2: Escrow as a Key to Meeting Data and Regulatory Requirements

a) From Source Code Safeguarding to Data Management: Rethinking Escrow

The second thematic session, moderated by Elke Bischof, Attorney-at-Law (MAYBURG Rechtsanwaltsgesellschaft mbH, Munich), was opened by Leon Hauzer (OSE; Escrow Alliance BV, Haarlem) with a presentation on the further development of the escrow concept.

He demonstrated that traditional escrow models – historically focused on source code deposits and insolvency scenarios – are no longer sufficient for modern digital services. Since today’s applications rely on cloud infrastructures, extensive data repositories and continuous deployment, source code may be legally available but often remains unusable in practice. The central question is therefore: “Can we continue operating a critical service if the service provider fails?”

Hauzer presented a broader understanding of escrow centred on continuity and encompassing data, software and infrastructure alike. Only in this way can the “product” or “service” be protected against loss through escrow. In addition, a shift from “deposit” to “recoverability” is required.

In this context, the Maturity Model was presented, which measures different maturity levels of escrow arrangements, ranging from the mere storage of data in a repository (R0 – traditional deposit) to demonstrated recoverability (R4 – verification). In his assessment, many companies believe themselves to be well prepared but in fact remain at a relatively low maturity level.

Further important observations concerned data management in the escrow context, which should not be understood as operational IT management but rather as a legal governance instrument. In a “trigger event” – such as the insolvency of a provider – the integrity, completeness and usability of the data must be legally assured.

One development he identified in escrow agreements is that modern escrow arrangements must place demonstrable recoverability at their core.

b) Beyond the Beaten Track: Practical Applications of Escrow

Stephan Peters then provided both a historical and practice-oriented overview of the development of escrow since the early 1980s. His presentation demonstrated that escrow has continually adapted to technological and legal developments – from traditional software escrow to data and cloud escrow and, more recently, forms such as SaaS continuity escrow and AI escrow.

The fundamental principle – resolving a conflict of interests between multiple parties – has remained unchanged, while the areas of application have expanded considerably.

Using numerous practical examples, Peters demonstrated the wide range of situations in which escrow is used today, from the deposit of dubbed versions of Hollywood productions and data escrow in the healthcare sector to safeguarding arrangements for long-term infrastructure projects, such as ensuring the maintainability of wind turbines.

A particular focus was placed on the distinction between cloud escrow and SaaS escrow. While cloud escrow is aimed at medium- to long-term reconstruction (“a toolkit for recovery”) and typically includes source code, containers, IaC elements and artefacts, SaaS escrow provides short-term protection against service outages (“immediate replacement on demand”).

These differences are reflected in costs, RTO/RPO values and testing frequencies: cloud escrow models generally cost between €5,000 and €25,000 per year, while SaaS escrow solutions range from €10,000 to €100,000 annually.

c) Escrow Unlocked: Making Seemingly Impossible DORA and NIS2 Requirements Possible

The presentation by Dr. Gregor Schmid, Attorney-at-Law (Taylor Wessing PartG mbB, Berlin) provided a concise overview of Regulation (EU) 2022/2554 (“DORA”) and demonstrated how escrow models can contribute to meeting the requirements laid down therein. DORA establishes, for the first time, a uniform EU framework for digital operational resilience in the financial sector.

The central question was how escrow can be used within this regulatory environment. It became clear that escrow – such as software escrow, cloud escrow or SaaS escrow – is relevant primarily as a “best practice” rather than as a mandatory requirement in situations where DORA requires, for example, recoverability, testability and control over critical ICT services. This includes source code reviews as part of resilience testing and ensuring ICT business continuity under Article 11 DORA. One practical scenario is the insolvency of an ICT third-party service provider.

The presentation also placed escrow within other regulatory frameworks such as MaRisk and NIS2. All of these frameworks contain similar requirements, albeit not in as much detail as DORA, and thus create corresponding use cases for escrow.

5. Thematic Session 3: AI and Data Protection – Smart Solutions

a) AI Use Case: Transcription

The final thematic session, moderated by Dr. Christiane Bierekoven, Attorney-at-Law, was opened by Carolin Loy (Bavarian State Office for Data Protection Supervision – BayLDA) with an overview of data protection issues relating to transcription in video conferences.

One initially surprising observation was that, out of approximately 10,000 complaints received in the previous year, not a single one related to this topic – although numerous requests for advice had been received.

Loy emphasised that no transcription tool is data protection-compliant per se; the specific use case and configuration are always decisive. When selecting a legal basis, consent is of only limited suitability, particularly in an employment context. Article 6(1)(b) GDPR is also difficult to rely on, since transcripts are generally not strictly necessary for the performance of a contract.

In practice, legitimate interests under Article 6(1)(f) GDPR are therefore frequently relied upon, with potential interests including increased efficiency, improved documentation or accessibility resulting from transcription. Nevertheless, it became clear that the assessment must be carried out carefully.

For this purpose, a multi-stage assessment framework was presented, consisting of Step 1 (Purpose Test), Step 2 (Necessity Test), Step 3 (Balancing Test) and Step 4 (Compliance Test). The final step includes consideration of other data protection obligations, such as information duties, rights of access and deletion obligations.

Finally, in a brief criminal-law excursus, Section 201 of the German Criminal Code (StGB) was considered, as it may be relevant to transcription and must therefore always be included in the assessment.

b) Data Protection-Compliant Cloud Use in the EU: Microsoft 365 and Copilot

Thomas Zerdick (European Data Protection Supervisor – EDPS, Brussels) provided detailed insights into the proceedings of the European Data Protection Supervisor against the European Commission regarding its use of Microsoft 365.

The investigation began in 2021 and concluded in March 2024 with a decision finding infringements of several important data protection requirements. Particular concerns arose in relation to purpose limitation, international transfers and unauthorised disclosure.

Zerdick explained how, in July 2025, the Commission was nevertheless able to achieve compliance through additional contractual provisions with Microsoft and supplementary technical and organisational measures adopted by the Commission and Microsoft for processing both within and outside the EEA.

A further focus was placed on the new challenges posed by Microsoft Copilot. Issues arise in relation to the origin of training data, personal data contained in prompts and outputs, and hallucinations. In this context, he referred to the EDPS Guidelines “Generative AI and the EUDPR” of October 2025. These provide practical guidance for EU institutions on the use of generative AI in compliance with the EUDPR, but may also be applied by analogy by organisations subject to the GDPR.

In conclusion, Zerdick identified specific points that public-sector bodies should take into account when using cloud services, such as clarifying responsibilities, documenting data flows to third countries and reviewing their Microsoft contracts to determine whether conditions similar to those agreed with the European Commission could be obtained.

c) AI and Data Protection: How to Get It Right

The topic was initially examined from a lawyer’s perspective by Dr. Robert Selk, Attorney-at-Law (SSH Rechtsanwälte PartG mbB Selk, Munich). He first pointed out that AI and data protection touch upon numerous areas, ranging from personal data in prompts or outputs to DPIA obligations and questions relating to automated decision-making.

The presentation focused on two aspects of particular practical relevance: (1) avoiding the processing of personal data and (2) determining the appropriate legal basis where such processing cannot be avoided.

The first question considered was whether personal data are contained in the training data of an LLM. Selk referred in this context to the judgment of Munich Regional Court I of 11 November 2025 (42 O 14139/24), which concerned an AI system capable of reproducing copyrighted song lyrics. The court considered it implausible that the outputs constituted random new creations and therefore found a copyright infringement.

This could also be relevant from a data protection perspective, for example where training data are contained verbatim in an LLM. In such circumstances, every use of an LLM by a user could potentially constitute processing relevant under data protection law.

The presentation then discussed anonymisation and pseudonymisation as tools for avoiding the processing of personal data. In the case of “true” anonymisation, data protection law ceases to apply. Pseudonymisation requires a more differentiated assessment and, in the context of the CJEU judgment of 4 September 2025 (C-431/23 P – SRB), may, for example, assist AI providers.

Where personal data are involved, Article 6(1)(f) GDPR will often be the relevant legal basis for users in practice. The Digital Omnibus envisages certain facilitations in this regard, in particular through a proposed Article 88c, which is intended to provide a statutory basis for the balancing of interests specifically in relation to AI development and AI operation.

Selk also referred to the discussion paper “The Bridge Blueprint”, published by the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI). The paper advances the proposition that the GDPR is sufficient for the use of AI – provided that it is interpreted correctly.

The topic was then considered from the provider’s perspective by Sebastian Dürdoth, in-house counsel (Microsoft Deutschland GmbH, Berlin). He emphasised that a proper legal assessment is only possible if the technical functioning of AI is understood.

It was explained that, at its core, AI functions as a kind of “language calculator” based on probabilities and does not possess memory in the conventional sense. Data hygiene is therefore particularly important when using AI in order to avoid “oversharing”.

Dürdoth presented a range of Microsoft data protection tools, including role and access-right concepts, Sensitivity Labels, Auto-Labelling and Purview DLP rules. He also highlighted contractual commitments made by Microsoft in connection with the use of Web Grounding within Copilot.

Finally, Dürdoth referred to Microsoft materials such as the M365 Toolkit, the “Cloud Compendium” and “Build Your Own DPIA”, which are intended to assist controllers in using Microsoft 365 and Copilot in compliance with data protection law.

6. Recalibrating AI Compliance: Concepts Based on Harmonised Standards and European Commission Guidelines

The symposium concluded with a presentation by Dr. Antonia von Appen, Attorney-at-Law (Noerr PartG mbB, Munich), which examined the practical implementation of the AI Act.

She explained that the AI Act is deliberately formulated in a technology-neutral manner and contains numerous indeterminate legal concepts – for example, the requirement that high-risk AI systems be designed and developed “in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity (…)” (Article 15(1) AI Act).

These indeterminate legal concepts are intended to reconcile the competing objectives of protecting fundamental rights, maintaining technological neutrality and promoting innovation. However, this leaves many issues of practical relevance unresolved.

Harmonised standards (Article 40 AI Act), codes of practice and guidelines serve to provide greater specificity as forms of soft law. As a general rule, however, they do not constitute binding interpretations, since the CJEU retains exclusive competence to interpret EU law.

Nevertheless, demonstrated compliance with harmonised standards gives rise to a presumption of conformity with the obligations applicable to high-risk AI systems (Article 40(1) AI Act). Conversely, in practice, market surveillance authorities appear increasingly inclined to regard non-compliance with harmonised standards as an indication of non-conformity.

Guidelines are an important indicator of conformity, and compliance with them must be taken into account when sanctions are imposed. Codes of practice can acquire EU-wide validity upon approval (Article 56(6), second subparagraph, AI Act), with adherence to them serving as evidence of compliance with AI Act obligations until harmonised standards are published.

Von Appen pointed out that only a small proportion of the relevant standards have been published so far, while many standards were expected only in early 2026. The corresponding provisions of the AI Act, however, are already set to become binding in August 2026. Companies therefore have only a few months after their publication to implement them – one of the major practical challenges.

For corporate compliance, this means, among other things, establishing risk-based AI governance and compliance structures and integrating standards at every level of internal processes. This entails a considerable additional workload for compliance departments due to the complexity and sheer number of soft-law components involved.

Author: Attorney-at-Law Dominik Hartl (OSE; CSW Rechtsanwälte Partnerschaft mbB, Munich)